CVE-2026-78629 UNKNOWN

CVE-2026-78629

Published: 2026-09-08

Description

The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptographic artifact, resulting in an unverifiable authentication verdict being delivered to the relying application.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…